94 wires and counting

$ follow Shopify

Keep up with Shopify in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

or

fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.

Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.

$ status

wire 2026-09-23
stories 45

© 2026 RepoJournal Home Showcase Explore How it works Privacy

$ the-wire · showcase

Shopify CLI groups App Security findings and guards agent scans

By RepoJournal · Filed · About Shopify · Composed from the cited sources · methodology

Shopify CLI made its App Security check quieter in the terminal and harder to accidentally overwrite, adding config support, rule-level grouping, and a scan guard that preserves agent findings.

Group repeated App Security findings in human-readable output Shopify/cli

by Josh Larson

The human-readable report now collapses repeated findings by rule, optional pattern, and severity, while JSON, traces, scoring, and check counts still keep every occurrence. Expect far less scrolling; expect nothing to change for consumers of the structured output.

Protect App security agent findings from new scans Shopify/cli

by Jason Kirtland

New scans are refused when agent findings or compiled review results already exist, so the deterministic check can no longer replace that work. Discarding the current review and starting over now requires the new --clean flag.

Harden app security scan safeguards Shopify/cli

by Jason Kirtland

Hardening on the same safeguard: --clean must be given explicitly and inherited environment values are ignored, and clean compilation is rejected before any artifacts are written. Command-boundary tests cover compiled-trace and findings protection.

Merge pull request #8578 from Shopify/joshlarson/app-doctor-config-flag Shopify/cli

by Josh Larson

The App Security Check now accepts --config, so scan configuration can be pointed at a file instead of relied on ambient defaults.

Merge pull request #8561 from Shopify/joshlarson/app-doctor-group-findings Shopify/cli

by Josh Larson

The grouping work landed alongside preserving every occurrence, so collapsed terminal output and full finding records no longer trade off against each other.

Quick answers

What shipped in Shopify on September 23, 2026?
Shopify CLI made its App Security check quieter in the terminal and harder to accidentally overwrite, adding config support, rule-level grouping, and a scan guard that preserves agent findings. In total, 31 commits and 14 pull requests landed.
Who contributed to Shopify on September 23, 2026?
2 developers shipped this update, including Josh Larson and Jason Kirtland.
What were the notable Shopify updates?
Group repeated App Security findings in human-readable output, Protect App security agent findings from new scans, and Harden app security scan safeguards.